OpenClaw discovered a critical authorization vulnerability in an Australian gym-booking website's API, which had zero checks preventing users from cancelling other people's reservations. The team verified the flaw by testing it on a person in waitlist position #1, successfully moving them up the queue.
Background
OpenClaw is an AI security research group that tests LLM agents for real-world vulnerabilities. This disclosure highlights the growing concern about AI agents interacting with production systems that lack proper authorization controls.
- Source
- Simon Willison
- Published
- Aug 10, 2026 at 10:05 AM
- Score
- 6.0 / 10